logo

Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels

ID: 0e4940dc-4bde-56ea-a879-b727d5f8678a

STIX ID: report--0e4940dc-4bde-56ea-a879-b727d5f8678a

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-05-29

Date Updated: 2026-05-29

Author: [email protected] (The Hacker News)

...
...

Kimsuky (aka Velvet Chollima) conducted targeted campaigns in Mar–Apr 2026 against South Korean military and corporate targets, using convincing lures (spoofed security software installers and a counterfeit Webex meeting page) to deliver the HTTPSpy RAT and related families (HelloDoor, HttpMalice, AppleSeed). The attacks used staged loaders (MemLoader.dll, encrypted JSE, PowerShell downloaders), persistence via scheduled tasks and VS Code remote tunneling/DWAgent, and novel techniques such as JSONPing and LLM/Rust-developed components; attackers likely used compromised meeting schedules/accounts for selective payload delivery and continued post-exploitation data collection and remote control.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.